FeedVulnerabilityPoC Exploit Released for FortiSandbox Vulnerability that All...
VulnerabilityCyber Security News
9.8CRITICAL

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

📅 18 April 2026 at 02:38 UTC📰 Cyber Security NewsView original source ↗
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login credentials. The vulnerability was originally discovered in November 2025 and has now been made public following Fortinet’s […] The post PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands appeared first on Cyber Security News.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A proof-of-concept exploit has been released for a critical vulnerability in Fortinet's FortiSandbox product, allowing an unauthenticated attacker to execute arbitrary operating system commands as root without requiring login credentials.

⚙️Technical Details
CVEs
CVE-2026-39808
Affected Systems
Fortinet Fortisandbox
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Organizations using Fortinet's FortiSandbox product, particularly those with unpatched systems
🛡️Recommended Actions
1Apply the patch for CVE-2026-39808 as soon as possible
2Monitor system logs for suspicious activity and implement additional security controls
3Conduct a thorough vulnerability assessment to identify potential entry points
📦Affected Products
Fortinet Fortisandbox
🔐NVD Verified DataVERIFIED
CVE-2026-39808CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected Products (CPE)
Fortinet Fortisandbox

Read the full article

This is a curated summary. The complete article is available at Cyber Security News.

Read on Cyber Security News
← Back to feed